"kerebos is the only game in town for 'single sign-on' traditional kerebos documention is rough author is a mean nerd. all network books spread the fear of hackers impersonating users. kerebos is used for password storage and encryption. :) history of kerebos: cerberus was the gatekeeper to hell!, and authenticated dead souls!!!:) kerberos stores all users passwords in a key distribution center! encryption software is not allowed to be exported outside of the US! three a's of kerberos authentication, authorization, and auditing. principal and realms all of these security protocols are extensively documented in RFC's kerberos still doesn't withhold against a brute force dictionary attack this pdf was put together horribly and i think it is missing pages all clocks on networked machines must be synchronized with NTP, network time protocol kerberos installation seems pretty straightforward.... unsynchronized clocks can cause strange errors! wow, book lists ways for hackers to crack kerberos program john the ripper can crack kerberos 4 kerberized clients have to run kerberos (like OpenSSH for unix and OS-X) windows and unix can work together with kerberos kerberos uses public key cryptography